Impact
The flaw is a stack‑based buffer overflow in the formSetFirewallRule function, triggered by an oversized firewall_name argument. This vulnerability, identified as CWE-119 and CWE-121, can be abused from a remote host to overwrite the return pointer on the stack, potentially allowing an attacker to execute arbitrary code and compromise the device’s confidentiality, integrity or availability. The CVSS score of 8.7 reflects the high severity of this remote attack.
Affected Systems
The issue exists solely on TRENDnet TEW‑432BRP devices running firmware 3.10B20, a unit that has been out of support since 2009. The vendor has stated it cannot replicate or patch the flaw, meaning the vulnerability remains only on legacy hardware that remains in use.
Risk and Exploitability
A public exploit demonstrates that the attack can be carried out without authentication from a remote host, elevating the risk for any network still hosting this device. Although the EPSS score is not available, the lack of an official fix, the EOL status of the product, and the confirmed remote execution capability make the threat highly likely. The vulnerability is not listed in CISA’s KEV catalog, but the high CVSS combined with the public exploit warrants immediate action to mitigate exposure.
OpenCVE Enrichment